ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 2 sources: “ZDI Discloses Two Linux Kernel IPv6 Use-After-Free Local Privilege Escalation Flaws (ZDI-26-623 and ZDI-26-683 / CVE-2026-72463)” — merged summary and timeline →

ZDI-26-623: Linux Kernel IPv6 Multicast Routing Use-After-Free Local Privilege Escalation Vulnerability

mediumAdvisoryimportance 42
AI summary · glm-5.3-flash

ZDI-26-623 details a use-after-free in Linux kernel IPv6 multicast routing enabling local privilege escalation, rated CVSS 8.8.

The Zero Day Initiative published ZDI-26-623 describing a use-after-free vulnerability in the Linux kernel's IPv6 multicast routing implementation. A local attacker who can execute low-privileged code on an affected installation can exploit the flaw to escalate privileges. ZDI assigned a CVSS rating of 8.8; the advisory does not name a CVE id or state that exploitation has been observed.

  • Use-after-free in Linux kernel IPv6 multicast routing
  • Requires local low-privileged code execution to exploit
  • CVSS score of 8.8 per ZDI
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.

This source does not provide full text. Read it at zerodayinitiative.com.